TechSpot

Almost 100% I've been keylogged

By freakqt
Dec 5, 2011
  1. Hey guys! :)

    Right, where to start.

    I'm almost 100% sure i've been keylogged
    Reason for that being is i've experienced first of all my Starcraft battlenet account was hacked some time ago, and that resulted in my old WoW account was openend again, the account then got banned by blizzard, and i had to call to get it unbanned. So a month after it got hacked again, and now its banned again. Haven't been arsed to get it unbanned since if i have a keylogger, then whats the point :)
    Anyway, so some days ago when i tried to log on my email, the password was changed. I then answer the security question, and when i get in my mailbox I get this "warning" popping by gmail, saying that they've seen me logged on from China. And yeah, im from Denmark

    So now i've tried to run through first of all malwarebytes, but it can't find anything.

    Right now im doing the 5-step Viruses/Spyware/Malware Preliminary Removal Instructions.

    And i will attacht the logs when im done.

    If you've got any questions please do so !

    Regards Freakqt. :)
     
  2. freakqt

    freakqt TS Rookie Topic Starter

    Here are the Logs. Pt 1. Malware bytelog

    Malwarebytes Anti-malware log




    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8315

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 7.0.6002.18005

    05-12-2011 17:20:52
    mbam-log-2011-12-05 (17-20-52).txt

    Skanningstype: Fuldstændig skanning (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|)
    Objekter skannet: 463513
    Tid gået: 2 time(e), 37 minut(ter), 44 sekund(er)

    Hukommelses Processorer Inficeret: 0
    Hukommelses Moduler Inficeret: 0
    Registreringsdatabasenøgler Inficeret: 0
    Registreringsdatabaseværdier Inficeret: 0
    Registreringsdatabasedata Objekter Inficeret: 0
    Inficerede Mapper: 0
    Inficerede Filer: 1

    Hukommelses Processorer Inficeret:
    (Ingen skadelige objekter blev fundet)

    Hukommelses Moduler Inficeret:
    (Ingen skadelige objekter blev fundet)

    Registreringsdatabasenøgler Inficeret:
    (Ingen skadelige objekter blev fundet)

    Registreringsdatabaseværdier Inficeret:
    (Ingen skadelige objekter blev fundet)

    Registreringsdatabasedata Objekter Inficeret:
    (Ingen skadelige objekter blev fundet)

    Inficerede Mapper:
    (Ingen skadelige objekter blev fundet)

    Inficerede Filer:
    c:\Users\Thomas\documents\crack\sony vegas pro 8.0b build 217-avchd-mpg-ac3 fixed\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
     
  3. freakqt

    freakqt TS Rookie Topic Starter

    Logs Pt 2 GMER

    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-12-05 21:03:53
    Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000057 ST350063 rev.3.CH
    Running: eksznzlr.exe; Driver: C:\Users\Thomas\AppData\Local\Temp\uxdiipoc.sys


    ---- System - GMER 1.0.15 ----

    SSDT 8F8A9E66 ZwCreateSection
    SSDT 8F8A9E70 ZwRequestWaitReplyPort
    SSDT 8F8A9E6B ZwSetContextThread
    SSDT 8F8A9E75 ZwSetSecurityObject
    SSDT 8F8A9E7A ZwSystemDebugControl
    SSDT 8F8A9E07 ZwTerminateProcess

    INT 0x51 ? 84D94BF8
    INT 0x52 ? 87270BF8
    INT 0x62 ? 87270BF8
    INT 0x82 ? 84D93BF8
    INT 0x92 ? 84D93BF8
    INT 0xA2 ? 84D94BF8

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!KeSetEvent + 215 820E0998 4 Bytes [66, 9E, 8A, 8F]
    .text ntkrnlpa.exe!KeSetEvent + 539 820E0CBC 4 Bytes [70, 9E, 8A, 8F]
    .text ntkrnlpa.exe!KeSetEvent + 56D 820E0CF0 4 Bytes [6B, 9E, 8A, 8F]
    .text ntkrnlpa.exe!KeSetEvent + 5D1 820E0D54 4 Bytes [75, 9E, 8A, 8F]
    .text ntkrnlpa.exe!KeSetEvent + 619 820E0D9C 4 Bytes [7A, 9E, 8A, 8F]
    .text ...
    ? System32\drivers\mblg.sys Den angivne sti blev ikke fundet. !
    ? System32\Drivers\spjk.sys Den angivne sti blev ikke fundet. !
    .text USBPORT.SYS!DllUnload 8A79441B 5 Bytes JMP 872701D8
    .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8F00B000, 0x3617E0, 0xE8000020]
    .text a4hbufvf.SYS 8F75D000 2 Bytes [82, 83]
    .text a4hbufvf.SYS 8F75D003 19 Bytes [82, 6C, 82, 00, 82, 60, 4F, ...]
    .text a4hbufvf.SYS 8F75D017 137 Bytes [00, 32, 87, 70, 80, 3D, 85, ...]
    .text a4hbufvf.SYS 8F75D0A1 43 Bytes [D0, 0D, 82, 74, C6, 07, 82, ...]
    .text a4hbufvf.SYS 8F75D0CE 10 Bytes [00, 00, 00, 00, 00, 00, C9, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; LEAVE ; HLT ; POP ESP; DEC EDX}
    .text ...

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8060C6D6] \SystemRoot\System32\Drivers\spjk.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8060C042] \SystemRoot\System32\Drivers\spjk.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8060C800] \SystemRoot\System32\Drivers\spjk.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [8060C0C0] \SystemRoot\System32\Drivers\spjk.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8060C13E] \SystemRoot\System32\Drivers\spjk.sys
    IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [8061BB90] \SystemRoot\System32\Drivers\spjk.sys
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortNotification] CC358B04
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortWritePortUchar] 838F783F
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] [100D8BA5] \Program Files\DAEMON Tools Lite\Engine.dll (Helper library/DT Soft Ltd)
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8F7810
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortStallExecution] 54771129
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortInitialize] B18D0502
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8
    IAT \SystemRoot\System32\Drivers\a4hbufvf.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Users\Thomas\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00382F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00382D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00382CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00382CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\jusched.exe[316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003E2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\jusched.exe[316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003E2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\jusched.exe[316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003E2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\jusched.exe[316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003E2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74BF7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74C4A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74BFBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74BEF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74BF75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74BEE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74C28395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74BFDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74BEFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74BEFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74BE71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74C7CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74C1C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74BED968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74BE6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74BE687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74BF2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009B2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [009B2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009B2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\Explorer.EXE[1876] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009B2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehmsas.exe[2332] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001F2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehmsas.exe[2332] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001F2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehmsas.exe[2332] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001F2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehmsas.exe[2332] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001F2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00412F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00412D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00412CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00412CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\System32\mobsync.exe[2828] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [000E2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\System32\mobsync.exe[2828] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [000E2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\System32\mobsync.exe[2828] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [000E2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\System32\mobsync.exe[2828] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [000E2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[3160] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B42F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[3160] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00B42D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[3160] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B42CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[3160] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B42CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehtray.exe[3412] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehtray.exe[3412] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehtray.exe[3412] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\ehome\ehtray.exe[3412] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Defender\MSASCui.exe[3464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01BC2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Defender\MSASCui.exe[3464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01BC2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Defender\MSASCui.exe[3464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01BC2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Defender\MSASCui.exe[3464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01BC2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\support\hpsysdrv.exe[3500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001E2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\support\hpsysdrv.exe[3500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001E2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\support\hpsysdrv.exe[3500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001E2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\support\hpsysdrv.exe[3500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001E2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\DAEMON Tools Lite\DTLite.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01BF2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\DAEMON Tools Lite\DTLite.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01BF2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\DAEMON Tools Lite\DTLite.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01BF2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\DAEMON Tools Lite\DTLite.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01BF2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Steam\Steam.exe[3536] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001B2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Steam\Steam.exe[3536] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001B2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Steam\Steam.exe[3536] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001B2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Steam\Steam.exe[3536] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001B2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00192F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00192D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00192CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00192CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe[3652] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe[3652] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe[3652] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe[3652] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe[3672] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00182F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe[3672] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00182D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe[3672] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00182CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe[3672] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00182CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\RtHDVCpl.exe[3692] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01DA2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\RtHDVCpl.exe[3692] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01DA2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\RtHDVCpl.exe[3692] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01DA2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\RtHDVCpl.exe[3692] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01DA2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001F2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001F2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001F2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[3764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001F2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\schtasks.exe[3808] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00102F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\schtasks.exe[3808] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00102D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\schtasks.exe[3808] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00102CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Windows\system32\schtasks.exe[3808] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00102CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[3928] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[3928] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[3928] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe[3928] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[3980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003E2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[3980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003E2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[3980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003E2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[3980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003E2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[4192] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01962F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[4192] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01962D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[4192] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01962CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Program Files\Windows Sidebar\sidebar.exe[4192] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01962CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\kbd\kbd.exe[4836] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\kbd\kbd.exe[4836] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\kbd\kbd.exe[4836] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\hp\kbd\kbd.exe[4836] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\Downloads\eksznzlr.exe[6700] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001B2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\Downloads\eksznzlr.exe[6700] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001B2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\Downloads\eksznzlr.exe[6700] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001B2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
    IAT C:\Users\Thomas\Downloads\eksznzlr.exe[6700] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001B2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 857241F8
    Device \FileSystem\fastfat \FatCdrom 87E291F8
    Device \Driver\sptd \Device\1066729066 spjk.sys

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3C 0x95 0xF5 0xF2 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x09 0x6A 0x8B 0xDF ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xEB 0x95 0xDC 0xA9 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAB 0x39 0xF4 0xCF ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x09 0x6A 0x8B 0xDF ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xEB 0x95 0xDC 0xA9 ...

    ---- EOF - GMER 1.0.15 ----
     
  4. freakqt

    freakqt TS Rookie Topic Starter

    Logs Pt 3. DDS and Attach

    DDS


    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_22
    Run by Thomas at 21:05:47 on 2011-12-05
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3070.1540 [GMT 1:00]
    .
    AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
    SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Windows\system32\schtasks.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Windows\system32\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\ehome\ehtray.exe
    C:\Users\Thomas\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
    C:\Program Files\DAEMON Tools Lite\DTLite.exe
    C:\Program Files\Steam\Steam.exe
    C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\hp\kbd\kbd.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files\Common Files\Steam\SteamService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://google.dk/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    TB: {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [Octoshape Streaming Services] "c:\users\thomas\appdata\roaming\octoshape\octoshape streaming services\OctoshapeClient.exe" -inv:bootrun
    uRun: [Google Update] "c:\users\thomas\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
    uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun: [KBD] c:\hp\kbd\KbdStub.EXE
    mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe"
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
    mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
    mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
    StartupFolder: c:\users\thomas\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\thomas\appdata\roaming\dropbox\bin\Dropbox.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Free YouTube to Mp3 Converter - c:\users\thomas\appdata\roaming\dvdvideosoftiehelpers\youtubetomp3.htm
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
    DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
    DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} - hxxp://webserver.dyyno.com/tng/dyyno-client/DyynoCAB.1.0.0.26.CAB
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
    TCP: DhcpNameServer = 212.242.40.3 212.242.40.51
    TCP: Interfaces\{48FB0E21-E3B2-4FBD-BB00-63344B46CF56} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{55A90B76-21EE-4CC8-9361-2C6DF1C6A65B} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{7FA9A152-845C-44ED-9303-B19A1C3785D5} : DhcpNameServer = 212.242.40.3 212.242.40.51
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\thomas\appdata\roaming\mozilla\firefox\profiles\vhggvxkw.default\
    FF - prefs.js: browser.startup.homepage - hxxp://tacky.dk/
    FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
    FF - component: c:\users\thomas\appdata\roaming\mozilla\firefox\profiles\vhggvxkw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
    FF - component: c:\users\thomas\appdata\roaming\mozilla\firefox\profiles\vhggvxkw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
    FF - plugin: c:\program files\dyyno\dyyno player\npvlc.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\users\thomas\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: c:\users\thomas\appdata\roaming\mozilla\firefox\profiles\vhggvxkw.default\extensions\npdyyno@dyyno.com\plugins\npDyyno.dll
    FF - plugin: c:\users\thomas\appdata\roaming\mozilla\plugins\npoctoshape.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    FF - Ext: Simple Dyyno Launcher: NPDyyno@dyyno.com - %profile%\extensions\NPDyyno@dyyno.com
    FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-11-9 36000]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
    R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-11-9 86224]
    R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-11-9 110032]
    R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2010-12-18 21992]
    R2 FontCache;Tjenesten Windows-skrifttypecache;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-5-24 21504]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-9-7 1153368]
    R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-11-26 6650368]
    R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-11-26 231936]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 PID_0920;Labtec WebCam(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2005-1-19 163328]
    S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2010-4-19 41984]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2011-12-05 16:27:15 -------- d-----w- c:\users\thomas\appdata\local\{17A1C84C-392D-46FC-AAAC-6C2AA8A6058A}
    2011-12-05 16:24:09 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{ac0835cc-457e-4d56-aa97-1e0980e3b53f}\offreg.dll
    2011-12-05 13:36:02 6823496 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{ac0835cc-457e-4d56-aa97-1e0980e3b53f}\mpengine.dll
    2011-12-05 13:28:58 -------- d-----w- c:\users\thomas\appdata\local\{59DDA14B-DB9B-407D-9B6F-8A2721B02059}
    2011-11-29 15:27:29 -------- d-----w- c:\users\thomas\appdata\local\{B1DD8BAB-36A7-4DA9-8AEA-A69DF78F9778}
    2011-11-28 16:44:48 -------- d-----w- c:\users\thomas\appdata\local\{9AA7918F-F37F-4706-978F-9DC0B2120FD9}
    2011-11-27 11:46:15 -------- d-----w- c:\users\thomas\appdata\local\{376F5DE1-20F3-4FE9-8419-63B54A00A344}
    2011-11-26 20:16:55 -------- d-----w- c:\users\thomas\appdata\local\{A9D96D02-5986-43DA-8D40-D2BF683AF246}
    2011-11-26 16:00:31 -------- d-----w- c:\users\thomas\appdata\local\SWTOR
    2011-11-26 01:00:45 -------- d-----w- c:\users\thomas\appdata\local\{9558274D-E20A-4426-9937-0A5D9EC03630}
    2011-11-24 20:44:32 -------- d-----w- c:\users\thomas\appdata\local\{541A9D72-C25A-4CC5-AC4A-E13631867D60}
    2011-11-24 15:45:28 -------- d-----w- c:\users\thomas\appdata\local\{2E915074-D49D-4527-9698-269FBE06BA5C}
    2011-11-22 17:13:41 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
    2011-11-22 17:12:55 -------- d-----w- c:\program files\common files\BioWare
    2011-11-22 16:55:53 -------- d-----w- c:\users\thomas\appdata\local\{377422F9-1FCE-42EC-9E1F-37C3A5EA3B4E}
    2011-11-21 17:35:10 -------- d-----w- c:\users\thomas\appdata\local\{2415FD0A-0E0F-47AD-85C0-5BDE29CC5E8D}
    2011-11-16 17:35:35 -------- d-----w- c:\users\thomas\appdata\local\{6733C420-A651-44F2-9EEF-DBA7B0DCD106}
    2011-11-12 11:44:17 -------- d-----w- c:\users\thomas\appdata\local\{A8855231-DE2B-4CC0-969F-6099ECFC7E92}
    2011-11-10 19:57:24 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-10 13:35:25 -------- d-----w- c:\users\thomas\appdata\local\{A401D1CC-553A-416F-AD18-B487946522FE}
    2011-11-09 12:09:57 -------- d-----w- c:\users\thomas\appdata\roaming\Avira
    2011-11-09 12:09:04 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
    2011-11-09 12:09:01 -------- d-----w- c:\programdata\Avira
    2011-11-09 11:56:27 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
    2011-11-09 11:54:36 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-11-09 11:54:35 707584 ----a-w- c:\program files\common files\system\wab32.dll
    2011-11-09 11:37:42 -------- d-----w- c:\users\thomas\appdata\local\{E54C870A-0CB9-4646-9096-208D9637B2F8}
    .
    ==================== Find3M ====================
    .
    2011-09-15 22:55:03 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    .
    ============= FINISH: 21:06:12,12 ===============


    Attach
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 22-03-2008 10:53:59
    System Uptime: 05-12-2011 17:23:38 (4 hours ago)
    .
    Motherboard: ASUSTek Computer INC. | | NARRA2
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | Socket AM2 | 2600/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 458 GiB total, 68,798 GiB free.
    D: is FIXED (NTFS) - 8 GiB total, 1,371 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is CDROM ()
    H: is Removable
    I: is Removable
    J: is Removable
    K: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    .
    ==== Installed Programs ======================
    .
    3DMark06
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.1.2 - Dansk
    Alchemy
    Amnesia - The Dark Descent
    Antares Autotune VST v5.09
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ASIO4ALL
    Astroburn Lite
    ATI Catalyst Install Manager
    ATITool Overclocking Utility
    µTorrent
    Audacity 1.2.6
    AutoUpdate
    Avira Free Antivirus
    Belkin 54g USB Network Adapter
    Bloodline Champions Beta
    Bonjour
    BurnInTest v4.0 Standard
    Cards_Calendar_OrderGift_DoMorePlugout
    Catalyst Control Center InstallProxy
    ccc-Branding
    Click to Call with Skype
    Collab
    CPUID HWMonitor 1.17
    Cubase 5
    Curse Client
    CyberLink DVD Suite Deluxe
    D3DX10
    DivX Codec
    DivX Converter
    DivX Player
    DivX Web Player
    Driver Sweeper 2.1.0
    Dropbox
    DyynoPlayer 0.8.6f.2
    FL Studio 8
    Fraps (remove only)
    Free Audio CD Burner version 1.4
    Free YouTube to MP3 Converter version 3.8
    Futuremark SystemInfo
    GameCenter
    GForce - Oddity
    Google Chrome
    Google Earth
    Google SketchUp 7
    Groovecube Exciton VSTi v1.2.2
    Guitar Pro 5.2
    Hardcore
    Hardware Diagnostic Tools
    Heroes of Newerth
    Hewlett-Packard Active Check
    Hewlett-Packard Asset Agent for Health Check
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Customer Experience Enhancements
    HP Customer Feedback
    HP Easy Setup - Frontend
    HP On-Screen Cap/Num/Scroll Lock Indicator
    HP Photosmart Essential 2.5
    HP Picasso Media Center Add-In
    HP Update
    HPPhotoSmartPhotobookWebPack1
    IL Download Manager
    IL Slicex
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 22
    Java(TM) SE Runtime Environment 6 Update 1
    Kompatibilitetspakke til Office 2007-systemet
    KORG Legacy Collection - M1
    KORG M1 Le
    LabelPrint
    Labtec Legacy USB Camera-driverpakke
    Lennar Digital Sylenth VSTi v1.2.1
    Lernout & Hauspie TruVoice American English TTS Engine
    LightScribe System Software
    Live 8.0.4
    Logitech Audio Echo Cancellation Component
    Logitech QuickCam
    Logitech QuickCam-driverpakke
    Logitech Video Enumerator
    M-Audio Key Rig 1.0.1
    Malwarebytes' Anti-Malware version 1.51.2.1300
    Microsoft .NET Framework 3.5 Language Pack SP1 - dan
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Client Profile DAN Language Pack
    Microsoft .NET Framework 4 Client Profile DAN sprogpakke
    Microsoft Application Error Reporting
    Microsoft Office PowerPoint Viewer 2007 (Danish)
    Microsoft Silverlight
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft Works
    Microsoft XNA Framework Redistributable 3.1
    minimoog V 1.6
    Mixed In Key 2.5
    MixMeister Studio 7.2.2
    Mozilla Firefox (3.6.24)
    MSVCRT
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Mumble and Murmur
    muvee autoProducer 6.1
    MVision
    Native Instruments FM8 v1.0.1.002 VSTi DXi RTAS
    Native Instruments Massive
    Octoshape add-in for Adobe Flash Player
    Octoshape Streaming Services
    OGA Notifier 2.0.0048.0
    Ohm Force - Ohmicide VST
    OpenAL
    Pirates, Vikings, & Knights II
    PoiZone
    Politikens Tysk-Dansk Dansk-Tysk Ordbog
    Power2Go
    PowerDirector
    PSSWCORE
    Python 2.5
    QuickTime
    Realtek High Definition Audio Driver
    Sausage Fattener
    Sawer
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile DAN sprogpakke (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile DAN sprogpakke (KB2518870)
    Segoe UI
    Skype™ 5.5
    Sony Vegas Pro 8.0
    Speakonia
    SpeedFan (remove only)
    Sprogpakke til Microsoft .NET Framework 3.5 SP1 - dansk
    Spybot - Search & Destroy
    Star Wars: The Old Republic
    StarCraft II
    Steam
    Sylenth1 v1.01.3
    System Requirements Lab
    TC Native Bundle v3.1
    Team Fortress 2
    TI InterActive!™
    Toxic Biohazard
    Udvidet multimedietastatur løsning
    Uninstall 1.0.0.1
    Unreal Tournament 3
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Vember Audio SURGE
    Ventrilo Client
    VideoToolkit01
    VirSyn Tera VSTi RTAS v3.2
    Virtual DJ - Atomix Productions
    Virtual DJ Pro Full - Atomix Productions
    VLC media player 1.0.5
    Voxengo Pristine Space VST 1.8
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Messenger
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    WinRAR arkivering
    World of Warcraft
    .
    ==== End Of File ===========================



    Right, that should be all hope this helps guys !
     
  5. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ============================================================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan:
    [​IMG]

    On completion of the scan click "Save log", save it to your desktop and post in your next reply:
    [​IMG]

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

    ============================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. freakqt

    freakqt TS Rookie Topic Starter

    New Logs

    ASWMBR LOG

    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-12-07 15:00:44
    -----------------------------
    15:00:44.491 OS Version: Windows 6.0.6002 Service Pack 2
    15:00:44.491 Number of processors: 2 586 0x6B02
    15:00:44.492 ComputerName: THOMAS-PC UserName: Thomas
    15:02:09.510 Initialize success
    15:03:12.405 AVAST engine defs: 11120700
    15:05:42.461 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000057
    15:05:42.463 Disk 0 Vendor: ST350063 3.CH Size: 476940MB BusType: 6
    15:05:44.481 Disk 0 MBR read successfully
    15:05:44.484 Disk 0 MBR scan
    15:05:44.500 Disk 0 unknown MBR code
    15:05:44.505 Disk 0 scanning sectors +976767120
    15:05:44.594 Disk 0 scanning C:\Windows\system32\drivers
    15:05:57.577 Service scanning
    15:05:58.258 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
    15:05:58.823 Modules scanning
    15:06:02.421 Disk 0 trace - called modules:
    15:06:02.432 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x857231f8]<<
    15:06:02.436 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x867d5ac8]
    15:06:02.441 3 CLASSPNP.SYS[8a9a58b3] -> nt!IofCallDriver -> [0x857b11c0]
    15:06:02.447 5 acpi.sys[807316bc] -> nt!IofCallDriver -> \Device\00000057[0x857b1600]
    15:06:02.452 \Driver\nvstor32[0x85800a38] -> IRP_MJ_CREATE -> 0x857231f8
    15:06:03.962 AVAST engine scan C:\Windows
    15:06:08.222 AVAST engine scan C:\Windows\system32
    15:09:13.076 AVAST engine scan C:\Windows\system32\drivers
    15:09:37.189 AVAST engine scan C:\Users\Thomas
    16:00:32.287 AVAST engine scan C:\ProgramData
    16:05:13.162 Scan finished successfully
    16:06:02.177 Disk 0 MBR has been saved successfully to "C:\Users\Thomas\Desktop\MBR.dat"
    16:06:02.185 The log file has been saved successfully to "C:\Users\Thomas\Desktop\aswMBR.txt"

    _______________________________________________________________
    COMBOFIX LOG

    ComboFix 11-12-06.02 - Thomas 07-12-2011 16:13:13.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3070.1757 [GMT 1:00]
    Kører fra: c:\users\Thomas\Downloads\ComboFix.exe
    AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
    SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\system32\jucheck.exe
    c:\windows\system32\jusched.exe
    .
    .
    ((((((((((((((((((((((((((((( Filer skabt fra 2011-11-07 til 2011-12-07 )))))))))))))))))))))))))))))))))))
    .
    .
    2011-12-07 13:55 . 2011-12-07 13:55 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E05BDEF-849E-4CCF-A32F-ACFDD4B73981}\offreg.dll
    2011-12-06 14:01 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E05BDEF-849E-4CCF-A32F-ACFDD4B73981}\mpengine.dll
    2011-11-26 16:00 . 2011-11-26 16:00 -------- d-----w- c:\users\Thomas\AppData\Local\SWTOR
    2011-11-22 17:13 . 2008-05-30 13:11 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
    2011-11-22 17:12 . 2011-11-22 17:12 -------- d-----w- c:\program files\Common Files\BioWare
    2011-11-22 17:12 . 2011-11-22 17:12 -------- d-----w- c:\program files\Electronic Arts
    2011-11-10 19:57 . 2011-11-10 19:57 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-09 12:09 . 2011-11-09 12:09 -------- d-----w- c:\users\Thomas\AppData\Roaming\Avira
    2011-11-09 12:09 . 2011-09-18 07:39 134344 ----a-w- c:\windows\system32\drivers\avipbb.sys
    2011-11-09 12:09 . 2011-09-15 22:55 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
    2011-11-09 12:09 . 2011-11-09 12:09 -------- d-----w- c:\programdata\Avira
    2011-11-09 11:56 . 2011-10-17 11:41 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
    2011-11-09 11:54 . 2011-09-20 21:02 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-11-09 11:54 . 2011-09-30 15:57 707584 ----a-w- c:\program files\Common Files\System\wab32.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-09-15 22:55 . 2009-11-29 10:53 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2007-08-24 13:52 . 2008-03-22 12:29 300400 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
    .
    .
    ((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Bemærk* tomme linier & lovlige standard linier vises ikke
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:36 94208 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:36 94208 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2010-10-06 23:36 94208 ----a-w- c:\users\Thomas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
    "Octoshape Streaming Services"="c:\users\Thomas\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    "Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
    "KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
    "OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 4702208]
    "SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
    "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
    .
    c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
    R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [x]
    R3 cpuz130;cpuz130;c:\users\Thomas\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
    R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
    R3 PID_0920;Labtec WebCam(PID_0920);c:\windows\system32\DRIVERS\LV532AV.SYS [2005-01-19 163328]
    R3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl.sys [2010-04-19 41984]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-06-21 691696]
    S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-15 36000]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
    S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-09-23 86224]
    S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
    S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
    .
    .
    --- Andre Services/Drivers i Hukommelsen ---
    .
    *NewlyCreated* - ASWMBR
    *Deregistered* - aswMBR
    *Deregistered* - avgntflt
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Indhold af mappen 'Planlagte Opgaver'
    .
    2011-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3475758902-2142473861-3379763625-1000Core.job
    - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-21 12:30]
    .
    2011-12-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3475758902-2142473861-3379763625-1000UA.job
    - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-21 12:30]
    .
    2011-12-05 c:\windows\Tasks\Norton Internet Security - Kør Fuld systemskanning - Thomas.job
    - c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 11:19]
    .
    .
    ------- Yderligere scanning -------
    .
    uStart Page = hxxp://google.dk/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    IE: Free YouTube to Mp3 Converter - c:\users\Thomas\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
    TCP: DhcpNameServer = 212.242.40.3 212.242.40.51
    FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\vhggvxkw.default\
    FF - prefs.js: browser.startup.homepage - hxxp://tacky.dk/
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    FF - Ext: Simple Dyyno Launcher: NPDyyno@dyyno.com - %profile%\extensions\NPDyyno@dyyno.com
    FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    .
    - - - - TOMME GENVEJE FJERNET - - - -
    .
    WebBrowser-{EFEED92A-A33D-4873-BA8F-32BAA631E54D} - (no file)
    HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    AddRemove-Sylenth1_is1 - c:\program files\Steinberg\VSTPlugins\Sylenth1\unins000.exe
    AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Thomas\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-12-07 16:21
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    scanner skjulte processer ...
    .
    scanner skjulte autostarter ...
    .
    scanner skjulte filer ...
    .
    scanning gennemført med succes
    skjulte filer: 0
    .
    **************************************************************************
    .
    Gennemført tid: 2011-12-07 16:24:27
    ComboFix-quarantined-files.txt 2011-12-07 15:24
    .
    Pre-Kørsel: 77.003.583.488 byte ledig
    Post-Kørsel: 77.133.664.256 byte ledig
    .
    - - End Of File - - 85ADF2E50A618CC8362A57DA1D735121
     
  7. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    All looks rather clean so I have a reason to believe that your Starcraft account had been simply hacked.
    It happens and no access to your computer is needed.
     
  8. freakqt

    freakqt TS Rookie Topic Starter

    Alright, thanks!

    Just seemed kind of weird that both my email and account was hacked from the same place in like 2 times in 3 months.


    Anyway Thanks!


    Regards :)
     
  9. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    You're very welcome [​IMG]
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...